Aggregator
[ .NET 安全代码审计 ] 从零基础到高阶实战,开启您的漏洞赏金之路
3 months 3 weeks ago
在当今数字化快速发展的时代,信息安全正成为企业生存与发展的核心保障,而代码审计则是信息安全防线中的关键环节。
获取窗口界面情报,通过 Sharp4FetchScreen 实现进程级别的隐蔽式截图
3 months 3 weeks ago
CSOP2025看点 | vivo陈心仪:基于博弈模型的办公终端攻防思路
3 months 3 weeks ago
CSOP 2025·深圳站 亮点前瞻
今起 AI 生成内容必须亮明身份;大疆双摄 Pocket 4 曝光;微信公号留言广告上线 | 极客早知道
3 months 3 weeks ago
· 优必选获 10 亿美元战略融资授信额度,计划在中东建「超级工厂」
利用NtReadVirtualMemory实现IAT中规避高危API
3 months 3 weeks ago
前世Win32 APIWin32 API实现最简单的Shellcode Loader如下,代码中包含注释,可以看到每条语句的含义上述代码编译执行后,Meterpreter可成功收到反连,如下图通过PE-bear查看,可以看到IAT中存在之前用到的几个Win32 API,如下图LoadLibrary、GetProcAddress然后进化出通过LoadLibrary、GetProcAddress实现的
CVE-2025-55291 | Shaarli up to 0.14.x cross site scripting (GHSA-7w7w-pw4j-265h / Nessus ID 260056)
3 months 3 weeks ago
A vulnerability has been found in Shaarli up to 0.14.x and classified as problematic. This vulnerability affects unknown code. The manipulation leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2025-55291. Local access is required to approach this attack. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2025-9749 | HKritesh009 Grocery List Management Web App up to f491b681eb70d465f445c9a721415c965190f83b /src/update.php ID sql injection (EUVD-2025-26314)
3 months 3 weeks ago
A vulnerability was found in HKritesh009 Grocery List Management Web App up to f491b681eb70d465f445c9a721415c965190f83b. It has been rated as critical. This affects an unknown part of the file /src/update.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2025-9749. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
vuldb.com
网络安全行业亟需并购与整合
3 months 3 weeks ago
2025年上半年,网络安全上市公司业绩持续下滑,单靠裁员降本难以实现真正的“增效”,行业亟需通过并购与整合来完成供给侧改革。本文指出中国网络安全产业正处于从规模扩张向集中阶段过渡的关键节点,巨头并购与生态壁垒将决定未来格局。
《电子数据取证与网络犯罪调查》专刊第八辑合作伙伴名录(二)
3 months 3 weeks ago
经过一段时间的筹备,《电子数据取证与网络犯罪调查》专刊第八辑合作伙伴名录出炉!
《电子数据取证与网络犯罪调查》专刊第八辑合作伙伴名录(一)
3 months 3 weeks ago
经过一段时间的筹备,《电子数据取证与网络犯罪调查》专刊第八辑合作伙伴名录出炉!
CVE-2025-9744 | Campcodes Online Loan Management System 1.0 /ajax.php?action=login Username sql injection (EUVD-2025-26307)
3 months 3 weeks ago
A vulnerability classified as critical was found in Campcodes Online Loan Management System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Executing manipulation of the argument Username can lead to sql injection.
This vulnerability is tracked as CVE-2025-9744. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2025-9745 | D-Link DI-500WF 14.04.10A1T jhttpd /version_upgrade.asp path os command injection (EUVD-2025-26310)
3 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection.
This vulnerability is listed as CVE-2025-9745. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2025-9746 | Campcodes Hospital Management System 1.0 Edit Doctor Specialization Page edit-doctor-specialization.php cross site scripting (EUVD-2025-26309)
3 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Campcodes Hospital Management System 1.0. This affects an unknown function of the file /admin/edit-doctor-specialization.php of the component Edit Doctor Specialization Page. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-9746. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-9747 | Koillection up to 1.6.18 csrf_protection_controller.js cross-site request forgery (Issue 1393 / EUVD-2025-26312)
3 months 3 weeks ago
A vulnerability was found in Koillection up to 1.6.18 and classified as problematic. Affected is an unknown function of the file assets/controllers/csrf_protection_controller.js. Such manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2025-9747. The attack can be executed remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
The vendor explains: "I ended up switching to a newer CSRF handling using stateless token."
vuldb.com
CVE-2025-9748 | Tenda CH22 1.0.0.1 httpd /goform/IPSECsave fromIpsecitem ipsecno stack-based overflow (EUVD-2025-26311)
3 months 3 weeks ago
A vulnerability was found in Tenda CH22 1.0.0.1. It has been declared as critical. Affected by this issue is the function fromIpsecitem of the file /goform/IPSECsave of the component httpd. Executing manipulation of the argument ipsecno can lead to stack-based buffer overflow.
This vulnerability appears as CVE-2025-9748. The attack may be performed from remote. There is no available exploit.
vuldb.com
对抗沙箱的银狐 vt首发2/69 Golang免杀样本
3 months 3 weeks ago
对抗沙箱的银狐 vt首发2/69 Golang免杀样本
3 months 3 weeks ago
当前环境出现异常,需完成验证后方可继续访问。
美团正式发布并开源 LongCat-Flash-Chat,动态计算开启高效 AI 时代
3 months 3 weeks ago
我们正式发布 LongCat-Flash-Chat,并同步开源。LongCat-Flash 采用创新性混合专家模型(Mixture-of-Experts, MoE)架构,总参数 560B,激活参数 18.6B~31.3B(平均 27B),实现了计算效率与性能的双重优化。
美团技术团队
Overview of Content Published in August
3 months 3 weeks ago
这篇文章概述了作者在八月份发布的博客文章和SANS ISC日记条目,包括pdf-parser.py的更新、Wireshark 4.4.9的发布以及pdf-parser处理所有流的功能介绍。